33
4
Installing and Configuring
Data Encryption Offloads
The 3C990B NIC performs data encryption processing offloads in a Windows 2000
environment. The 3C990B NIC does not encrypt the data itself: the operating system
performs that function.
Encryption processing is handled entirely by the 3XP processor on the NIC. The 3XP
processor enables true end-to-end network security at the data capacity of the connected
network cable, without sacrificing performance.
The data encryption offload capability of the 3C990B NIC is disabled when you first
unpack it. U.S. law requires that users be certified to use certain data encryption products.
This chapter describes how to obtain the proper certification and enable encryption
offloading on the 3C990B NIC by:
■
Downloading the 3Com 3C990 Security Software Utility from the 3Com Corporation
World Wide Web site.
■
Running the Security Software Utility to install DES/3DES encryption on the
3C990B NIC.
This chapter also provides instructions for:
■
Disabling Data Encryption on the 3C990B NIC.
■
Upgrading Data Encryption on the 3C990B NIC from 56-bit DES to 168-bit 3DES.
■
Configuring IPSec In Windows 2000 environments.
Overview
Internet Protocol Security (IPSec) is a framework of open standards for ensuring secure
private communications over IP networks. IPSec ensures confidentiality, integrity, access
control, and authenticity of data communications across a public IP network.
Offloading Encryption Processing
You can configure any two (or more) computers running Windows 2000 to perform IPSec
encryption by changing the Local Security Setting in the operating system. With most non-
3C990B NICs, all the IPSec processing is done by the host central processing unit (CPU),
which significantly diminishes CPU performance. The 3C990B NIC can
offload
all the
encryption processing from the host CPU, thereby freeing the CPU to work on other tasks.
For any two or more computers running non-Windows 2000 operating systems
(Windows 95/98/Me/NT), IPSec encryption is provided by third-party applications. The
3C990B NIC does not provide IPSec encryption offloading for those operating systems.